cbcvebase.
CVE-2024-52965
published 2025-07-08

CVE-2024-52965: A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10…

PriorityP348high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.25%
16.3th percentile
A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.13 and before 7.0.20 allows an API-user using api-key + PKI user certificate authentication to login even if the certificate is invalid.

Affected

20 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortios
fortinetfortios
fortinetfortios
fortinetfortios>= 7.0.1 < 7.0.177.0.17
fortinetfortios7.0.1 – 7.0.16
fortinetfortios>= 7.2.0 < 7.2.117.2.11
fortinetfortios7.2.0 – 7.2.10
fortinetfortios>= 7.4.0 < 7.4.67.4.6
fortinetfortios7.4.0 – 7.4.5
fortinetfortios7.6.0 – 7.6.1
fortinetfortiproxy
fortinetfortiproxy>= 7.0.0 < 7.0.217.0.21
fortinetfortiproxy7.0.0 – 7.0.20
fortinetfortiproxy>= 7.2.0 < 7.2.147.2.14
fortinetfortiproxy7.2.0 – 7.2.13
fortinetfortiproxy>= 7.4.0 < 7.4.97.4.9
fortinetfortiproxy7.4.0 – 7.4.8
fortinetfortiproxy>= 7.6.0 < 7.6.27.6.2
fortinetfortiproxy7.6.0 – 7.6.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.